webmcp/analysis

PaperVeil

A browser-local medical appeal desk where agents get capabilities—not identity—with one-field consent, adversarial leak blocking, and an auditable disclosure ledger.

Aggregate 38
Leverage 10
Execution 9
Impact 9
Creativity 10

Each criterion 1–10, equally weighted; aggregate is their sum. Ranking is the pipeline's consolidated output.

01 Links & metadata

Category
health / health
Origin
built for the challenge / built for the challenge
Access
no auth
Eligibility
LIKELY_ELIGIBLE / LIKELY_ELIGIBLE
Substitution
TRANSFORMATIVE / MAJOR_DELTA
Demo liveness
alive

Origin, access model, eligibility, and substitution are reviewer diagnostics, not judging criteria. Authentication requirements are not penalized.

02 The two blind reviews

Two independent reviewers scored this project blind, from a sanitized evidence packet. Scores are shown separately so the reasoning stays inspectable. A withheld score means the reviewers differed by more than two points.

Reviewer A (round 1)

confidence 80%
Leverage
9 /10

The live case, one-field consent, fail-closed disclosure boundary, and auditable ledger require shared page state and agent capabilities rather than opaque identity access; generic UI automation is materially less reliable.

Evidence cited
  • Seven narrow tools operate on browser-local IndexedDB case state.
  • Sensitive raw identifiers require one-time human allow/deny/expiry.
  • Seeded prompt injection is marked untrusted and attempted leakage is blocked.
Execution
8 /10

The packet describes a complete adversarial workflow and the frame sheets/promotional UI show a coherent appeal desk, though there is no transcript or live observation.

Evidence cited
  • Demo reported alive, public repository, and four frame sheets submitted.
  • Description covers evidence, policy, disclosure, draft, and export paths.
  • Packaging screenshot visibly shows privacy firewall, synthetic evidence, policy matches, and disclosure ledger.
Impact
9 /10

People appealing medical denials have a real need for document interpretation and drafting while facing serious exposure of identifiers and health information.

Evidence cited
  • Description names codes, deadlines, missing evidence, and sensitive identifiers.
  • Capability-not-identity model and auditable disclosure directly address the privacy risk.
Creativity
9 /10

The capability-not-identity framing and adversarial leak-blocking demonstration are original and deeply aligned with the agent medium.

Evidence cited
  • One-field consent is integrated into the tool interaction.
  • Prompt-injected request for member ID is treated as an explicit red-team boundary case.

Reviewer B (round 2)

confidence 79%
Leverage
8 /10

Structured, shared case state and explicit disclosure gates materially outperform generic UI driving for privacy-sensitive appeal work; the agent receives capabilities rather than identity.

Evidence cited
  • Seven narrow tools are described for evidence, line items, policy rules, scenarios, disclosure, drafting, and export.
  • Human and agent share a live case with one-field consent and a fail-closed adversarial demonstration.
  • Frame sheets show a structured appeal workspace, boundary/visibility states, and checkable defects.
Execution
7 /10

The packet presents a coherent, intentional workflow and substantial UI evidence, but no actual video transcript or final end-to-end runtime proof is supplied.

Evidence cited
  • Contact sheets show a rendered outpatient imaging appeal with structured metadata, warnings, workflow panels, and later privacy/defect views.
  • Devpost packaging describes browser-local state, consent, ledger, and tests, but the screenshot itself is promotional packaging.
Impact
8 /10

People appealing denied medical claims have a concrete high-stakes need for policy/evidence assistance without exposing identity; the privacy-aware workflow credibly addresses it using synthetic claims.

Evidence cited
  • Pitch identifies medical-claim appealers needing help with codes, deadlines, missing evidence, and policy rules.
  • The product explicitly separates useful capabilities from sensitive identifiers and records disclosure decisions.
Creativity
8 /10

The capability-not-identity framing, adversarial prompt-injection boundary test, and two-visibility appeal model are a fresh and memorable application of WebMCP.

Evidence cited
  • Seeded OCR prompt injection is used as a red-team scenario.
  • Frames show one letter with two visibility levels and an appeal built around checkable defects.

03 Review highlights

Standouts across reviewers

  • Excellent privacy threat model.
  • Concrete adversarial demonstration rather than generic privacy claims.
  • Capability-not-identity privacy model.
  • Fail-closed prompt-injection demonstration with explicit disclosure consent.
  • Auditable, shared case state.

Red flags

  • All claim data is synthetic and no transcript is supplied.
  • Promotional screenshot cannot independently verify blocking behavior.
  • No submitted video or transcript; visual evidence is contact sheets and a promotional Devpost image.
  • Final real-world submission or claim resolution is not shown; data is synthetic.

04 Evidence

What each artifact proves is labeled on the artifact itself. A Devpost page capture is packaging evidence, not proof the product runs; video frames are evidence from the submitted demo, not live verification.

Devpost page capture for PaperVeil
EX-01 Devpost page capture · packaging evidence, not runtime proof · source

EX-V Submitted demo video

Contact sheets from the ?s video the team submitted. This is what reviewers were shown; it demonstrates the product in motion but is not independent verification. · watch the original

Contact sheet 1 from the PaperVeil demo video
EX-V1 Sheet 1 of 3 · reported video evidence
Contact sheet 2 from the PaperVeil demo video
EX-V2 Sheet 2 of 3 · reported video evidence
Contact sheet 3 from the PaperVeil demo video
EX-V3 Sheet 3 of 3 · reported video evidence